Privacy Policy
This policy explains what Scoutflow collects, why it is used, and the choices available to you.
Effective September 19, 2026
Information we collect
Scoutflow stores the information needed to operate your account and CRM workspace.
- Account information, including your name, email address, password hash, role, and sign-in activity.
- CRM content you provide, such as campaigns, prospects, company and contact details, notes, outreach history, follow-ups, tags, and imported CSV data.
- Configuration data, including reminder preferences, integration settings, and API tokens. Sensitive values are encrypted where supported.
- Basic extension telemetry, including downloads, an anonymous installation identifier, extension version, and last-active time. Scoutflow does not use this to record general browsing history.
- Operational information needed for security and reliability, such as server logs, error details, and request metadata.
How we use information
- Provide, secure, maintain, and improve Scoutflow.
- Keep each invited user's CRM workspace private from other users.
- Run requested AI scouting or chat actions and requested Google Drive backup or restore operations.
- Send account emails such as invitations and password-reset messages.
- Diagnose failures, prevent abuse, and understand whether the Scoutflow extension is configured and active.
Third-party services
When you enable an integration, relevant information is sent to that provider only to perform the action you request. OpenAI may process campaign instructions, prospect research, and outreach context for AI features. Google processes OAuth and Drive data for backups. LinkedIn pages are read by the optional browser extension to support actions you initiate.
Those providers process data under their own terms and privacy policies. Scoutflow never asks for or stores your Google or LinkedIn password.
Storage, retention, and security
Hosted CRM data is stored in Scoutflow's configured database and separated by user account. Local editions keep their primary database on the device. Google Drive backups are created only when that feature is connected and used. OpenAI API keys are excluded from ordinary backups.
We use reasonable technical controls, including hashed passwords, access controls, and encryption for supported secrets. No online service can guarantee absolute security. Data may be retained while an account remains active and for a reasonable period afterward for backups, legal obligations, fraud prevention, and service recovery.
Your choices and rights
You can edit or delete CRM records, disconnect integrations, revoke API tokens, and export or back up supported data. You may request access, correction, export, or deletion of account data through the contact page. Some records may be retained when required by law or necessary for security and dispute resolution.
Cookies and local storage
Scoutflow uses essential session cookies to keep you signed in and browser storage for preferences such as theme and extension settings. Scoutflow does not use these essential technologies for third-party advertising.
Changes and contact
We may update this policy as Scoutflow changes. Material updates will be reflected by a revised effective date. Questions and privacy requests can be submitted through the Verthscale contact page.